mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-10-03 13:30:36 +00:00
Merge #248911: python3Packages.pymdown-extensions: patch CVE-2023-32309
...into staging-23.05
This commit is contained in:
@@ -1,11 +1,18 @@
|
||||
{ lib
|
||||
, buildPythonPackage
|
||||
, fetchFromGitHub
|
||||
, fetchpatch
|
||||
, hatchling
|
||||
, pytestCheckHook
|
||||
, markdown
|
||||
, pyyaml
|
||||
, pygments
|
||||
|
||||
# for passthru.tests
|
||||
, mkdocstrings
|
||||
, mkdocs-material
|
||||
, mkdocs-mermaid2-plugin
|
||||
, hydrus
|
||||
}:
|
||||
|
||||
let
|
||||
@@ -48,6 +55,28 @@ buildPythonPackage rec {
|
||||
hash = "sha256-ld3NuBTjDJUN4ZK+eTwmmfzcB8XCtg8xaLMECo95+Cg=";
|
||||
};
|
||||
|
||||
patches = [
|
||||
(fetchpatch {
|
||||
name = "CVE-2023-32309.part-1.patch";
|
||||
url = "https://github.com/facelessuser/pymdown-extensions/commit/b7bb4878d6017c03c8dc97c42d8d3bb6ee81db9d.patch";
|
||||
excludes = [
|
||||
"docs/src/markdown/about/changelog.md"
|
||||
"docs/src/markdown/extensions/snippets.md"
|
||||
"pymdownx/__meta__.py"
|
||||
];
|
||||
hash = "sha256-JQRgtTfcy9Hrzj84dIxvz7Fpzv3JYKbil6B3BUPIkMw=";
|
||||
})
|
||||
(fetchpatch {
|
||||
name = "CVE-2023-32309.part-2.patch";
|
||||
url = "https://github.com/facelessuser/pymdown-extensions/commit/7c13bda5b7793b172efd1abb6712e156a83fe07d.patch";
|
||||
excludes = [
|
||||
"docs/src/markdown/about/changelog.md"
|
||||
"pymdownx/__meta__.py"
|
||||
];
|
||||
hash = "sha256-3lVz2Ezw0fM2QVA6dfKllwpfDbEKl+YSoy2DHuUGIjY=";
|
||||
})
|
||||
];
|
||||
|
||||
nativeBuildInputs = [ hatchling ];
|
||||
|
||||
propagatedBuildInputs = [ markdown pygments ];
|
||||
@@ -59,6 +88,10 @@ buildPythonPackage rec {
|
||||
|
||||
pythonImportsCheck = map (ext: "pymdownx.${ext}") extensions;
|
||||
|
||||
passthru.tests = {
|
||||
inherit mkdocstrings mkdocs-material mkdocs-mermaid2-plugin hydrus;
|
||||
};
|
||||
|
||||
meta = with lib; {
|
||||
description = "Extensions for Python Markdown";
|
||||
homepage = "https://facelessuser.github.io/pymdown-extensions/";
|
||||
|
||||
Reference in New Issue
Block a user